
GIAC Certified Forensic Analyst
Domain 2Objective 3
Analyzing Volatile Windows Event Artifacts GCFA Practice Questions (Page 6)
Part of the Memory Forensics domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 7–12 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
8concepts
Questions 26–30
- 26
You are constructing a timeline from a memory dump. You have the following events: (1) Event ID 4624 logon at 10:00:00, (2) Event ID 4688 process creation for cmd.exe at 10:01:00, (3) Event ID 5156 network connection to an external IP at 10:02:00, and (4) Event ID 1102 Security log cleared at 10:03:00. Which sequence of events is most likely to represent an attacker's actions?
Select an answer first - 27
You are investigating a system where a driver failed to load. In the memory dump, you find Event ID 219 (Kernel-PnP) from the System log. Which additional event log record would best help you determine why the driver failed?
Select an answer first - 28
Which event log is most likely to contain an error related to a third-party application crashing?
Select an answer first - 29
Which of the following is a common tool or plugin used to extract event log records from a Windows memory dump?
Select an answer first - 30
You are analyzing a memory dump and find an Event ID 4624 (logon) with a logon type of 2 (interactive) at 09:00:00. You also find a process (explorer.exe) with a start time of 09:00:05 and a user-association to the same account. Which conclusion is most strongly supported by correlating these artifacts?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFA” is a trademark of its owner, used for identification only.